Netgear ReadyCloud TLS Cert Validation Bypass MiTM Attacks
CVE-2026-0420 Published on June 9, 2026

Missing TLS certificate validation in NETGEAR's ReadyCloud client app
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-0420 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE

Weakness Type

Missing Cryptographic Step

The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.


Affected Versions

NETGEAR RAX120v1: NETGEAR RAX120v2: NETGEAR RAX35: NETGEAR RAX38: NETGEAR RAX40:

Exploit Probability

EPSS
0.14%
Percentile
3.39%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.